gogs_0_day_attackers is a temporary cluster name for operators observed actively exploiting CVE-2025-8110, a remote code execution vulnerability in Gogs. The activity is associated with opportunistic compromise of exposed public Gogs servers and post-compromise deployment of Supershell malware. Observed tradecraft indicates rapid weaponization of a newly disclosed server-side vulnerability for initial access, followed by execution of malware on victim systems. Public reporting tied the activity to attackers creating repositories with randomized naming patterns on compromised Gogs instances. Attribution to a specific named intrusion set, country, or long-term campaign is not currently available from the supplied facts. The available evidence supports characterization as active exploit operators focused on internet-exposed developer infrastructure, with confirmed capabilities in initial access, post-exploitation, and malware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.